Mail transmission method based on quantum local area network

Through the mail transmission method based on the quantum LAN, local authentication and differentiated key distribution of mail systems are used to solve the problems of low key management efficiency and complex data transmission in the prior art, and efficient and secure quantum encrypted mail transmission is achieved.

CN120582913AActive Publication Date: 2025-09-02中电信量子信息科技集团有限公司

Patent Information

Application Number
CN202511091185.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-05
Publication Date
2025-09-02
Estimated Expiration
2045-08-05

AI Technical Summary

Technical Problem

In the existing quantum encrypted mail transmission scheme, the key management efficiency and data transmission efficiency are poor. The authentication process relies on cross-system interaction, which increases the delay and complexity. In the mass mail scenario, each group of receiving terminals needs to generate a key separately, which increases the burden on the server.

Method used

The mail transmission method based on the quantum LAN is adopted, and local authentication and differentiated key distribution of the mail system are used, and identity authentication is directly used to use the pre-stored second authentication key to support multi-target terminal transmission, and quantum symmetric keys are distributed according to the terminal's online status, reducing cross-system communication and transit links.

Benefits of technology

It improves the response speed of identity authentication, supports multi-terminal encrypted transmission, reduces authentication delay and resource waste, improves the transmission efficiency and security of quantum encrypted emails, and reduces server load.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120582913A_ABST
    Figure CN120582913A_ABST
Patent Text Reader

Abstract

The invention discloses a mail transmission method based on a quantum local area network. The quantum local area network comprises a sending terminal, a first centralized control station, a second centralized control station and a secret mail system, wherein the first centralized control station, the second centralized control station and the secret mail system establish communication connection with the sending terminal. The method comprises the following steps: the sending terminal sends a first authentication key and mail summary information of a to-be-sent target mail to the secret mail system; and then, the secret mail system authenticates the sending terminal according to the first authentication key and a second authentication key pre-stored in the secret mail system. Then, the encrypted mail system determines a target terminal according to the mail summary information under the condition that the authentication of the sending terminal is passed, and the target terminal establishes communication connection with the second centralized control station; and finally, the encrypted mail system distributes the generated first quantum symmetric key according to the online state of the target terminal at the current moment so as to carry out encrypted transmission on the target mail. Thus, according to the online state of the target terminal, differential distribution processing is performed on the first quantum symmetric key, and the transmission efficiency and the resource utilization rate can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of quantum encryption communication, and more specifically, to a method for transmitting emails based on a quantum local area network. Background Art

[0002] Related technologies can encrypt emails using quantum keys, preventing cyberattacks during transmission and ensuring email security. However, in quantum encrypted email transmission scenarios, these solutions often require encrypted email forwarding via a server, resulting in poor key management and data transmission efficiency. Summary of the Invention

[0003] The present application provides a method for transmitting emails based on a quantum local area network.

[0004] The embodiments of the present application provide a method for transmitting mail based on a quantum local area network, wherein the quantum local area network includes a sending terminal, a first centralized control station communicating with the sending terminal, a second centralized control station, and a secret mail system. The method includes: The sending terminal sends a first authentication key and email summary information of a target email to be sent to the secret email system; The secret mail system authenticates the sending terminal according to the first authentication key and a second authentication key pre-stored in the system; When the sending terminal passes authentication, the secret mail system determines the target terminal according to the mail summary information, and the target terminal establishes a communication connection with the second centralized control station; The encrypted mail system distributes the generated first quantum symmetric key according to the online status of the target terminal at the current moment, so as to encrypt and transmit the target mail.

[0005] In this way, the sending terminal sends the first authentication key and the email digest of the target email to be sent to the encrypted email system. The encrypted email system then authenticates the sending terminal based on the first authentication key and its pre-stored second authentication key. If the sending terminal passes authentication, the encrypted email system determines the target terminal based on the email digest, and the target terminal establishes a communication connection with the second centralized control station. Finally, the encrypted email system distributes the generated first quantum symmetric key based on the current online status of the target terminal to encrypt the target email for transmission. In this way, the encrypted email system directly performs local matching authentication based on its pre-stored second authentication key, reducing redundant key exchange steps during the authentication process and improving the response speed of identity authentication. Furthermore, by locating the target terminal through the email digest and associating it with the corresponding second centralized control station, it can support quantum encrypted email transmission scenarios where "one sending terminal sends multiple target terminals." Furthermore, the encrypted email system performs differentiated distribution of the first quantum symmetric key based on the online status of the target terminal, which can improve the transmission efficiency and resource utilization of quantum encrypted emails in complex network environments.

[0006] In some embodiments, authenticating the sending terminal based on the first authentication key and a pre-stored second authentication key includes: If the second authentication key matches the first authentication key, the encrypted mail system determines that the sending terminal passes authentication; In the case that the second authentication key does not match the first authentication key, the secret mail system determines that the sending terminal authentication fails.

[0007] In this way, if the second authentication key matches the first authentication key, the cryptographic mail system determines that the sending terminal has passed authentication. If the second authentication key does not match the first authentication key, the cryptographic mail system determines that the sending terminal has failed authentication. In this way, the cryptographic mail system directly calls its own pre-stored second authentication key to match the first authentication key submitted by the sending terminal locally, eliminating the need for interactive authentication with an external quantum cryptography management service system in traditional solutions, reducing cross-system communication delays and redundant processes, and improving authentication response speed.

[0008] In certain embodiments, the method further comprises: The secret mail system terminates the mail transmission when the sending terminal fails in authentication.

[0009] In this way, the encrypted email system terminates email transmission if the sending terminal fails authentication. This timely termination of the process in the event of authentication failure can avoid subsequent unnecessary key generation, distribution, and data encryption transmission operations, reducing ineffective resource usage.

[0010] In some embodiments, distributing the generated first quantum symmetric key according to the current online status of the target terminal includes: When the target terminal is online at the current moment, the secret mail system sends the first quantum key in the first quantum symmetric key to the first centralized control station based on the quantum channel; The secret mail system sends the second quantum key in the first quantum symmetric key to the second central control station based on the quantum channel.

[0011] In this way, if the target terminal is currently online, the secret mail system sends the first quantum key from the first quantum symmetric key to the first centralized control station via the quantum channel. Next, the secret mail system sends the second quantum key from the first quantum symmetric key to the second centralized control station via the quantum channel. In this way, if the target terminal is currently online, the first quantum key and the second quantum key are distributed to the first centralized control station associated with the sending terminal and the second centralized control station associated with the target terminal, respectively, via the quantum channel, ensuring that the quantum keys are not eavesdropped or tampered with during the distribution process, allowing for subsequent use of the quantum keys to process emails.

[0012] In certain embodiments, the method further comprises: The first centralized control station encrypts the target email according to the received first quantum key to generate first encrypted information; The first centralized control station sends the first encrypted information to the second centralized control station.

[0013] In this way, the first centralized control station encrypts the target email using the received first quantum key, generating a first encrypted message. The first centralized control station then transmits the first encrypted message to the second centralized control station. This eliminates the need for the encrypted email system to process the target email, thus minimizing the risk of the target email being leaked within the encrypted email system. Combined with the unbreakable nature of quantum keys, this establishes an end-to-end secure transmission link from the sending terminal to the receiving terminal. Furthermore, this end-to-end secure transmission link from the sending terminal to the receiving terminal reduces latency in intermediate links, thereby improving encrypted transmission efficiency.

[0014] In certain embodiments, the method further comprises: The second centralized control station decrypts the first encrypted information according to the received second quantum key to generate the target email; The second centralized control station sends the target email to the target terminal.

[0015] The second centralized control station then decrypts the first encrypted message using the received second quantum key, generating the target email. The second centralized control station then sends the target email to the target terminal. The second centralized control station then decrypts the first encrypted message using the second quantum key that matches the first quantum key. Only when the keys fully match can the target email be restored, ensuring that the email content has not been tampered with during transmission.

[0016] In some embodiments, distributing the generated first quantum symmetric key according to the current online status of the target terminal includes: When the target terminal is in an offline state at a current moment, the secret mail system sends the first quantum key in the first quantum symmetric key to the first centralized control station based on the quantum channel.

[0017] In this way, if the target terminal is currently offline, the secret mail system sends the first quantum key in the first quantum symmetric key to the first centralized control station via the quantum channel. This way, when the target terminal is offline, the secret mail system only distributes the first quantum key to the first centralized control station via the quantum channel, avoiding wasting quantum channel bandwidth and key resources if the target terminal is unable to respond.

[0018] In certain embodiments, the method further comprises: The first centralized control station encrypts the target email according to the received first quantum key to generate first encrypted information; The first centralized control station sends the first encrypted information to the encrypted mail system.

[0019] In this way, the first centralized control station encrypts the target email using the received first quantum key, generating a first encrypted message. The first centralized control station then sends the first encrypted message to the encrypted email system. In this way, the first centralized control station encrypts the target email using the first quantum key distributed through the quantum channel, generating a first encrypted message that possesses the high security of quantum encryption.

[0020] In certain embodiments, the method further comprises: The encrypted mail system receives the first encrypted information; The secret mail system decrypts the first encrypted information according to the second quantum key in the first quantum symmetric key, generates the target mail, and stores it.

[0021] In this way, the secret mail system receives the first encrypted message. Using the second quantum key within the first quantum symmetric key, the secret mail system decrypts the first encrypted message, generates the target email, and stores it. In this way, the first encrypted message is decrypted using the second quantum key, converting the target email into plaintext for storage, providing the basis for subsequent re-encryption and forwarding using the new key.

[0022] In certain embodiments, the method further comprises: The secret mail system periodically monitors the online status of the target terminal at preset intervals; When detecting that the target terminal is online, the cryptographic mail system generates a second quantum symmetric key; The secret mail system sends the third quantum key in the second quantum symmetric key to the second central control station; The secret mail system encrypts the target mail according to the fourth quantum key in the second quantum symmetric key to generate a second encrypted message; The secret mail system sends the second encrypted information to the second centralized control station.

[0023] In this way, the secret mail system periodically monitors the online status of the target terminal at preset intervals. Then, if the target terminal is detected to be online, the secret mail system generates a second quantum symmetric key. The system then sends the third quantum key from the second quantum symmetric key to the second centralized control station. Subsequently, the secret mail system encrypts the target email using the fourth quantum key from the second quantum symmetric key to generate a second encrypted message. Finally, the secret mail system sends the second encrypted message to the second centralized control station. This avoids the key management costs required for long-term storage of encrypted information while ensuring the security of the target email transmission through secondary encryption.

[0024] In certain embodiments, the method further comprises: The second centralized control station receives the third quantum key sent by the cryptographic mail system; The second centralized control station decrypts the second encrypted information according to the third quantum key to generate the target email; The second centralized control station sends the target email to the target terminal.

[0025] In this way, the second centralized control station receives the third quantum key sent by the encrypted mail system. Next, the second centralized control station decrypts the second encrypted message using the third quantum key, generating the target email. Finally, the second centralized control station sends the target email to the target terminal. This ensures that the target email remains protected by quantum encryption during its secondary forwarding from the encrypted mail system to the target terminal, maintaining high security throughout the entire link.

[0026] Additional aspects and advantages of the embodiments of the present application will be given in part in the description below, and in part will become obvious from the description below, or will be learned through practice of the embodiments of the present application. BRIEF DESCRIPTION OF THE DRAWINGS

[0027] The above and / or additional aspects and advantages of the present application will become apparent and easily understood from the description of the embodiments in conjunction with the following drawings, in which: Figure 1 This is one of the flow charts of the email transmission method according to the embodiment of the present application; Figure 2 This is a schematic diagram of a quantum local area network according to an embodiment of the present application; Figure 3 This is the second flow chart of the email transmission method according to the embodiment of the present application; Figure 4 This is the third flow chart of the email transmission method according to the embodiment of the present application; Figure 5 This is the fourth flow chart of the email transmission method according to the embodiment of the present application; Figure 6 This is the fifth flow chart of the email transmission method according to the embodiment of the present application; Figure 7 This is the sixth flow chart of the email transmission method according to the embodiment of the present application; Figure 8 This is a signaling diagram of a mail transmission method in which the target terminal is in an offline state according to an embodiment of the present application; Figure 9 This is the seventh flow chart of the email transmission method according to the embodiment of the present application; Figure 10 This is the eighth flow chart of the email transmission method according to the embodiment of the present application; Figure 11 This is the ninth flowchart of the email transmission method according to the embodiment of the present application; Figure 12 This is the tenth flowchart of the email transmission method according to the embodiment of the present application; Figure 13 This is the eleventh flow chart of the email transmission method according to the embodiment of the present application; Figure 14 This is a signaling diagram of the mail transmission method when the target terminal is in an offline state according to an embodiment of the present application. DETAILED DESCRIPTION

[0028] The embodiments of the present application are described in detail below. Examples of the embodiments are shown in the accompanying drawings, wherein the same or similar reference numerals represent the same or similar elements or elements having the same or similar functions throughout. The embodiments described below with reference to the accompanying drawings are exemplary and are only used to explain the embodiments of the present application, and should not be understood as limiting the embodiments of the present application.

[0029] In current practical applications of quantum communication technology, email content can be encrypted using quantum keys. Leveraging the underlying principles of quantum mechanics (such as quantum non-cloning and measurement collapse), quantum keys effectively resist various cyberattacks during transmission. Even if an eavesdropper attempts to intercept or crack the key, their manipulation will be detected in real time due to the altered quantum state, thus ensuring the security of emails during transmission.

[0030] However, in the specific transmission scenario of quantum encrypted email, the authentication process of related technical solutions often relies on the quantum cryptography management service system to complete the entire process: the authentication key sent by the terminal must first be transmitted to the quantum cryptography management service system. After the quantum cryptography management service system completes the authentication, it returns the authentication result to the encrypted email system, which then determines whether the authentication is passed based on the authentication result. This cross-system round-trip interaction not only prolongs the authentication process, but also increases management complexity because the authentication key needs to flow between multiple nodes.

[0031] Furthermore, the email transmission process of related technical solutions generally adopts a "terminal → server → terminal" transit mode, that is, the sending terminal must first send the email to the encrypted email system, which then distributes it to the receiving terminal. In this way, since the security of quantum encryption relies on key consistency throughout the entire link, to ensure that the overall transmission complies with quantum encryption standards, each link from the sending terminal to the server, and then from the server to the receiving terminal must undergo separate quantum key distribution and encryption operations. For example, the sending terminal needs to use the first set of quantum keys to encrypt the email and transmit it to the encrypted email system. After receiving it, the encrypted email system needs to re-encrypt it with the second set of quantum keys before forwarding it to the receiving terminal. If quantum encryption is not used in any link (or the keys do not match), the quantum security of the entire transmission link will be invalidated, reducing it to the level of traditional encryption.

[0032] In addition, at the data transmission level, the relevant technical solutions require that emails be decrypted and re-encrypted in transit on the server, regardless of whether the receiving terminal is online. This process increases the server's computing power consumption and storage pressure, especially in mass email scenarios. Each group of receiving terminals needs to generate keys separately and repeat the transit process. The overall operational complexity is significantly increased, which seriously restricts the practicality and promotion efficiency of quantum encrypted emails.

[0033] Based on the above questions, please refer to Figure 1The embodiments of the present application provide a method for transmitting mail based on a quantum local area network. The quantum local area network includes a sending terminal, a first centralized control station that establishes a communication connection with the sending terminal, a second centralized control station, and a secret mail system. The method includes: 01: The sending terminal sends the first authentication key and the email summary information of the target email to be sent to the confidential email system; 02: The secret mail system authenticates the sending terminal based on the first authentication key and its own pre-stored second authentication key; 03: When the sending terminal passes the authentication, the confidential mail system determines the target terminal based on the email summary information, and the target terminal establishes a communication connection with the second centralized control station; 04: The secret mail system distributes the generated first quantum symmetric key according to the online status of the target terminal at the current moment to encrypt the target email for transmission.

[0034] Specifically, a quantum local area network refers to a local communication network within a metropolitan area built based on quantum communication technology. The quantum local area network includes nodes such as sending terminals, receiving terminals, centralized control stations, encrypted mail systems, and target terminals. It implements quantum key distribution through quantum channels, supports quantum encrypted communication between networked devices, and ensures secure information transmission between devices in the area. Figure 2 , Figure 2 Schematic diagram of quantum local area network.

[0035] The sending terminal refers to the user device that initiates email sending (such as a mobile phone, computer, etc.). It needs to insert a quantum security chip (such as a SIM card, U-shield) to store and call the authentication key. It is the source of the target email and is responsible for sending authentication information and email-related data to the confidential email system.

[0036] The first centralized control station is located within the quantum local area network and is directly connected to the sending terminal. Equipped with QKD equipment, it receives quantum keys from the key system and email data from the sending terminal. It encrypts the email data using the quantum key and transmits it via a classical channel. It serves as a service node for the sending terminal to access the quantum network.

[0037] The second centralized control station refers to a centralized control station located within the quantum local area network and directly associated with the target terminal. The second centralized control station is also an access service station within the quantum local area network. It establishes a communication connection with the target terminal and is capable of receiving quantum keys and encrypted emails sent by the key system. It uses quantum keys to decrypt encrypted emails and forwards them to the target terminal. It is the node through which the target terminal accesses the quantum local area network. It is connected to the first centralized control station via quantum channels such as optical fibers and supports quantum encryption communications. It should be noted that there is no substantial difference in function or structure between the first and second centralized control stations. Their names are simply used to distinguish the attributes of the terminals they are associated with (e.g., corresponding to the sending terminal and the target terminal, respectively). There is no difference in functional importance or priority.

[0038] The encrypted email system integrates a quantum cryptography management service system and an encrypted email server, which also integrates a quantum cryptography management subsystem. The encrypted email system receives authentication keys and performs matching authentication, identifies target terminals, and generates and distributes quantum keys based on the terminal's online status, coordinating the authentication, key management, and email transmission control of quantum encrypted emails.

[0039] The first authentication key refers to a key randomly extracted by the sending terminal from the set of authentication keys used for the encrypted email service in the quantum security chip. This key is used by the sending terminal to prove its legitimacy to the encrypted email system and serves as the identity authentication credential for initiating quantum encrypted email. It should be noted that the authentication key in the quantum security chip has a key identifier to clarify its purpose.

[0040] The second authentication key refers to a key pre-stored in the quantum cryptography management subsystem (specifically, in the quantum cryptography management subsystem). Specifically, when a user activates the quantum cryptography function, their terminal device is equipped with a quantum security chip (such as a SIM card or USB shield), and the quantum security chip is loaded with an authentication key Ka specifically for the quantum cryptography service. This authentication key Ka is clearly marked with the quantum cryptography service type and configured with a unique key identifier. During key loading, the corresponding key Ka' is pre-stored in the quantum cryptography management subsystem. This configuration ensures that the quantum security chip and the quantum cryptography management subsystem each hold matching symmetric keys, providing the foundation for subsequent authentication and verification. The quantum cryptography system authenticates the sending terminal by comparing the second authentication key with the first authentication key, ensuring the legitimacy of the sending terminal's identity.

[0041] The target email refers to the email content edited by the user at the sending terminal and needs to be transmitted to the recipient through quantum encryption. It is the core data object of encrypted transmission.

[0042] The email summary includes the user information of the recipient (i.e., the target terminal) and is sent by the sending terminal to the encrypted email system after successful authentication. The email summary is used by the encrypted email system to determine the target terminal's identity and is the key basis for determining the transmission path.

[0043] The target terminal refers to the terminal device (such as a mobile phone or computer) used by the email recipient and equipped with a quantum security chip. It establishes a communication connection with the second centralized control station and is the recipient of the target email. The location of the target terminal depends on the email summary information, which includes the target terminal's identifier (such as the terminal ID and the user account to which it belongs). The confidential email system first uses these identifiers to identify the target terminal.

[0044] It should be noted that the target terminal may include multiple terminal devices, that is, a user can send emails to multiple users through the sending terminal. As long as these target terminals all establish a communication connection with the same centralized control station, email transmission can be carried out according to the quantum local area network-based email transmission method provided in this application, and the same set of quantum symmetric keys can be used. If these target terminals establish communication connections with different centralized control stations, the encrypted email system needs to generate and distribute corresponding quantum symmetric keys for the centralized control station corresponding to each target terminal. Each centralized control station completes encrypted transmission with the associated target terminal based on the key it receives, ensuring that target terminals covered by different centralized control stations can all receive emails securely.

[0045] The online status of a target terminal refers to whether the target terminal is within the range of the quantum local area network (QLAN) capable of establishing a quantum cryptographic communication connection and is addressable. The encrypted mail system uses this determination to determine whether to adopt direct transmission or transit storage. In certain embodiments, upon receiving the email summary and first authentication key, and upon successful authentication of the sending terminal, the encrypted mail system immediately sends a status query request (e.g., a heartbeat signal or communication link test packet) to the target terminal, inquiring whether the second centralized control station maintains a normal communication connection with the target terminal, thereby determining the target terminal's online status.

[0046] The first quantum symmetric key refers to the symmetric quantum key generated by the secret mail system (specifically generated by the quantum cryptography management subsystem) for the encrypted transmission of the target email, which is used to encrypt and protect the transmitted email data.

[0047] First, when initiating an email sending request, the sending terminal extracts the first authentication key from the authentication key set dedicated to the confidential email service in its own quantum security chip, and sends it to the confidential email system, triggering the encrypted transmission process.

[0048] Next, when the quantum cryptography management service system in the email system recognizes that the received quantum key is an authentication key specifically for the email service, it directly transfers the authentication operation to the quantum cryptography management subsystem in the email server. The quantum cryptography management subsystem then uses its own pre-stored second authentication key to compare it with the first authentication key sent by the sending terminal to perform identity authentication. This eliminates the need for the quantum cryptography management service system to complete authentication itself and then return the authentication result to the email server, thereby improving key management efficiency and shortening authentication time.

[0049] Then, after the identity authentication of the sending terminal is passed, the confidential mail system locates the target terminal according to the email summary information and confirms the second centralized control station that is connected to the target terminal, providing a basis for subsequent transmission path planning.

[0050] Finally, the encrypted email system determines whether the target terminal is currently online (that is, whether the target terminal is within the range of the quantum local area network that can establish a quantum encryption communication connection and can be addressed), and distributes the generated first quantum symmetric key based on the current online status of the target terminal to encrypt the target email.

[0051] In summary, in the quantum local area network-based email transmission method provided in the embodiments of the present application, the sending terminal sends a first authentication key and email digest information of the target email to be sent to the encrypted email system. The encrypted email system then authenticates the sending terminal based on the first authentication key and its own pre-stored second authentication key. If the sending terminal passes authentication, the encrypted email system determines the target terminal based on the email digest information, and the target terminal establishes a communication connection with the second centralized control station. Finally, the encrypted email system distributes the generated first quantum symmetric key based on the current online status of the target terminal to encrypt the target email for transmission. In this way, the encrypted email system directly performs matching authentication locally based on its own pre-stored second authentication key, reducing redundant key exchange steps during the authentication process and improving the response speed of identity authentication. Furthermore, by locating the target terminal through the email digest information and associating it with the corresponding second centralized control station, it can support quantum encrypted email transmission scenarios where "one sending terminal sends multiple target terminals." Furthermore, the encrypted email system performs differentiated distribution of the first quantum symmetric key based on the online status of the target terminal, which can improve the transmission efficiency and resource utilization of quantum encrypted emails in complex network environments.

[0052] See also Figure 3 In some embodiments, step 02 (authenticating the sending terminal based on the first authentication key and the second authentication key pre-stored in the terminal) includes: 021: If the second authentication key matches the first authentication key, the encrypted mail system determines that the sending terminal has passed the authentication; 022: In the case that there is no second authentication key that matches the first authentication key, the secret mail system determines that the sending terminal authentication fails.

[0053] Specifically, after receiving the first authentication key, the encrypted email system compares it with all stored second authentication keys. If any of the second authentication keys matches the first, the sending terminal's identity is deemed legitimate, and authentication succeeds. If no second authentication key matches the first, the sending terminal's identity is deemed unacceptable, and authentication fails. This ensures that only legitimate terminal devices can access the quantum LAN.

[0054] In this way, if the second authentication key matches the first authentication key, the cryptographic mail system determines that the sending terminal has passed authentication. If the second authentication key does not match the first authentication key, the cryptographic mail system determines that the sending terminal has failed authentication. In this way, the cryptographic mail system directly calls its own pre-stored second authentication key to match the first authentication key submitted by the sending terminal locally, eliminating the need for interactive authentication with an external quantum cryptography management service system in traditional solutions, reducing cross-system communication delays and redundant processes, and improving authentication response speed.

[0055] See also Figure 4 In certain embodiments, the method further comprises: 05: The confidential email system terminates email transmission if the sending terminal authentication fails.

[0056] Specifically, the failure of the sending terminal to authenticate may be due to the sending terminal not being authorized to activate the quantum encrypted email function, the key in the quantum security chip being tampered with or damaged, or the terminal device being illegally counterfeited, which means that the sending terminal may not have legal quantum encrypted email transmission authority. In such cases, after detecting the key matching failure, the encrypted email system will immediately interrupt all subsequent email transmission-related processes, including stopping the parsing of email summary information, terminating the generation and distribution of quantum keys, and refusing to receive or process email data from the sending terminal. In this way, it can block the possibility of unauthorized terminals accessing the quantum encryption transmission link, preventing illegal terminals from sending emails or stealing key resources by forging identities.

[0057] In this way, the encrypted email system terminates email transmission if the sending terminal fails authentication. This timely termination of the process in the event of authentication failure can avoid subsequent unnecessary key generation, distribution, and data encryption transmission operations, reducing ineffective resource usage.

[0058] See also Figure 5 In some embodiments, step 04 (distributing the generated first quantum symmetric key according to the current online status of the target terminal) includes: 041: When the target terminal is online at the current moment, the secret mail system sends the first quantum key in the first quantum symmetric key to the first centralized control station based on the quantum channel; 042: The secret mail system sends the second quantum key in the first quantum symmetric key to the second centralized control station based on the quantum channel.

[0059] Specifically, a quantum channel refers to a dedicated communication channel built based on the principles of quantum mechanics, which is used to securely transmit quantum keys. It has anti-eavesdropping properties (because quantum state measurement will cause collapse, eavesdropping behavior can be detected in real time), ensuring that quantum keys are not stolen or tampered with during the distribution process, providing a security foundation for subsequent email encryption.

[0060] The first quantum key refers to the encryption key generated by the secret mail system and sent to the first centralized control station through the quantum channel. It is used by the first centralized control station to encrypt the target mail, ensuring that the mail data of the sending terminal is encrypted by the quantum-level key before entering the transmission link, thereby ensuring source security.

[0061] The second quantum key is sent by the encrypted email system to the second centralized control station through the quantum channel, and is used by the second centralized control station to decrypt the received encrypted email. The first quantum key and the second quantum key form a pair of symmetric keys.

[0062] After the secret mail system sends a status query request to the second centralized control station associated with the target terminal and confirms through link connectivity testing (such as heartbeat response and communication link test) that the target terminal is currently online (i.e., maintaining a normal communication connection with the second centralized control station and within the coverage of the quantum channel), the secret mail system generates a pair of first quantum symmetric keys for the encrypted email transmission. Subsequently, the secret mail system, using the quantum channel, sends the first quantum key to the first centralized control station associated with the sending terminal, ensuring that the sending terminal can obtain the key required for encryption. Simultaneously, the secret mail system also sends the second quantum key to the second centralized control station associated with the target terminal, ensuring that the receiving terminal can obtain the key required for decryption.

[0063] In this way, if the target terminal is currently online, the secret mail system sends the first quantum key from the first quantum symmetric key to the first centralized control station via the quantum channel. Next, the secret mail system sends the second quantum key from the first quantum symmetric key to the second centralized control station via the quantum channel. In this way, if the target terminal is currently online, the first quantum key and the second quantum key are distributed to the first centralized control station associated with the sending terminal and the second centralized control station associated with the target terminal, respectively, via the quantum channel, ensuring that the quantum keys are not eavesdropped or tampered with during the distribution process, allowing for subsequent use of the quantum keys to process emails.

[0064] See also Figure 6 , the method further comprises: 043: The first centralized control station encrypts the target email according to the received first quantum key to generate first encrypted information; 044: The first centralized control station sends the first encrypted information to the second centralized control station.

[0065] Specifically, the first encrypted information refers to the encrypted data generated after the first centralized control station encrypts the target email using the first quantum key.

[0066] After the first centralized control station confirms that the target terminal is online and receives the first quantum key in the encrypted email system, it uses the first quantum key to encrypt the target email. The encrypted email is then transmitted to the second centralized control station via a classical network channel. This ensures that email transmission in online scenarios is protected by quantum-level keys and bypasses server transfer to improve efficiency.

[0067] In this way, the first centralized control station encrypts the target email using the received first quantum key, generating a first encrypted message. The first centralized control station then transmits the first encrypted message to the second centralized control station. This eliminates the need for the encrypted email system to process the target email, thus minimizing the risk of the target email being leaked within the encrypted email system. Combined with the unbreakable nature of quantum keys, this establishes an end-to-end secure transmission link from the sending terminal to the receiving terminal. Furthermore, this end-to-end secure transmission link from the sending terminal to the target terminal reduces latency in intermediate links, thereby improving encrypted transmission efficiency.

[0068] See also Figure 7 , the method further comprises: 045: The second centralized control station decrypts the first encrypted information based on the received second quantum key to generate the target email; 046: The second centralized control station sends the target email to the target terminal.

[0069] Specifically, after receiving the second quantum key sent by the encrypted email system via the quantum channel and the first encrypted message sent by the first centralized control station via the classical network channel, the second centralized control station uses the second quantum key to decrypt the first encrypted message, restoring the target email. The second centralized control station then sends the decrypted target email to the corresponding destination terminal, completing the email transmission. In this way, through the coordination of quantum key synchronization between centralized control stations and data transmission via the classical channel, secure decryption and direct transmission of quantum-encrypted emails between online terminals are achieved, avoiding the delays and security risks that may arise from emails being relayed through servers.

[0070] The second centralized control station then decrypts the first encrypted message using the received second quantum key, generating the target email. The second centralized control station then sends the target email to the target terminal. The second centralized control station then decrypts the first encrypted message using the second quantum key that matches the first quantum key. Only when the keys fully match can the target email be restored, ensuring that the email content has not been tampered with during transmission.

[0071] The following is a complete example to illustrate the method of sending emails when the target terminal is offline. Figure 8 , Figure 8 The signaling diagram of the email transmission method when the target terminal is offline is shown in FIG. The sending terminal is client A, the target terminal is client B, the first centralized control station is centralized control station A, and the second centralized control station is centralized control station B.

[0072] First, there's the identity authentication phase (Client A → Quantum Cryptography Management Service System → Confidential Email Server): Client A submits the authentication key Ka (including the key identifier used to identify the client) to the Quantum Cryptography Management Service System and simultaneously sends an email digest directly to the Confidential Email Server. Subsequently, the Quantum Cryptography Management Service System recognizes the key identifier as the authentication key and forwards it to the Quantum Cryptography Management Subsystem. Finally, the Quantum Cryptography Management Subsystem verifies the received Ka against the stored key Ka'. If verification succeeds, authentication is successful and the online status of Client B is determined.

[0073] Next, the quantum key distribution and email encryption phase (encrypted email server → centralized control station A / B, centralized control station A → centralized control station B): When client B is online, the encrypted email server sends the generated first quantum key K1 to centralized control station A via the quantum channel (dashed line); it also sends the generated second quantum key K2 to centralized control station B. Centralized control station A then encrypts the original email data using the received quantum key K1, generating the first encrypted message. The encrypted email is then sent from centralized control station A to centralized control station B via the classical network. Centralized control station B then decrypts the email using the received quantum key K2, restoring the target email. Finally, centralized control station B forwards the decrypted target email to client B.

[0074] See also Figure 9 In some embodiments, step 04 (distributing the generated first quantum symmetric key according to the current online status of the target terminal) includes: 047: When the target terminal is offline at the current moment, the secret mail system sends the first quantum key in the first quantum symmetric key to the first centralized control station based on the quantum channel.

[0075] Specifically, when the secret mail system sends a status query request to the second centralized control station associated with the target terminal and confirms through link connectivity detection (such as heartbeat response, communication link test) that the target terminal is currently offline (that is, the target terminal is not connected to the quantum local area network, or cannot respond to the communication request), the secret mail system generates a first quantum symmetric key and distributes the first quantum key only to the first centralized control station associated with the sending terminal through the quantum channel.

[0076] In this way, if the target terminal is currently offline, the secret mail system sends the first quantum key in the first quantum symmetric key to the first centralized control station via the quantum channel. This way, when the target terminal is offline, the secret mail system only distributes the first quantum key to the first centralized control station via the quantum channel, avoiding wasting quantum channel bandwidth and key resources if the target terminal is unable to respond.

[0077] See also Figure 10 In certain embodiments, the method further comprises: 048: The first centralized control station encrypts the target email according to the received first quantum key to generate a first encrypted message; 049: The first centralized control station sends the first encrypted message to the secret mail system.

[0078] Specifically, if the target terminal is currently offline, the first centralized control station receives the first quantum key sent by the encrypted email system via a quantum channel. The first centralized control station then uses this first quantum key to encrypt the target email, generating a first, unreadable encrypted message, ensuring that the email content cannot be decrypted by unauthorized parties during transmission. The first encrypted message is then sent to the encrypted email system via a classical network channel, which then processes it based on the target terminal's online status.

[0079] In this way, the first centralized control station encrypts the target email using the received first quantum key, generating a first encrypted message. The first centralized control station then sends the first encrypted message to the encrypted email system. In this way, the first centralized control station encrypts the target email using the first quantum key distributed through the quantum channel, generating a first encrypted message that possesses the high security of quantum encryption.

[0080] See also Figure 11 In certain embodiments, the method further comprises: 050: The encrypted mail system receives the first encrypted message; 051: The secret mail system decrypts the first encrypted information according to the second quantum key in the first quantum symmetric key, generates the target email, and stores it.

[0081] Specifically, the secret mail system receives a first encrypted message sent by a first centralized control station via a classical network channel. The system then extracts a second quantum key from the generated first quantum symmetric key and uses the second quantum key to decrypt the received first encrypted message, restoring the plaintext content of the target email and ensuring its integrity and accuracy. After decryption, the secret mail system stores the target email plaintext in a local secure storage area. In some embodiments, the secret mail system can protect the target email plaintext through its own local encryption mechanism (e.g., storage encryption).

[0082] Quantum encryption follows the "one-time, one-pad" principle, meaning the same key is used for only one transmission and cannot be reused. Therefore, the first encrypted message is encrypted using the "first quantum key," which is only valid for the transmission link from the sending terminal to the encrypted email system. Once the target terminal comes online, a new quantum symmetric key must be generated (rather than reusing the first quantum key) for forwarding to meet the security requirements of quantum encryption.

[0083] In this way, the secret mail system receives the first encrypted message. Using the second quantum key within the first quantum symmetric key, the secret mail system decrypts the first encrypted message, generates the target email, and stores it. In this way, the first encrypted message is decrypted using the second quantum key, converting the target email into plaintext for storage, providing the basis for subsequent re-encryption and forwarding using the new key.

[0084] See also Figure 12 In certain embodiments, the method further comprises: 052: The secret mail system periodically monitors the online status of the target terminal at preset intervals; 053: When the target terminal is detected to be online, the secret mail system generates a second quantum symmetric key; 054: The secret mail system sends the third quantum key in the second quantum symmetric key to the second centralized control station; 055: The secret mail system encrypts the target mail according to the fourth quantum key in the second quantum symmetric key to generate a second encrypted message; 056: The secret mail system sends the second encrypted information to the second centralized control station.

[0085] Specifically, the preset duration refers to a fixed time interval (such as 1 minute or 5 minutes) set by the confidential email system to trigger regular checks on the target terminal's online status. This allows for timely detection of target terminals online while preventing frequent monitoring from consuming excessive system resources, achieving a balance between real-time performance and resource consumption.

[0086] Periodic monitoring refers to the online status detection mechanism that the confidential email system repeatedly executes according to the preset duration, and continuously obtains the connection status of the target terminal by sending query requests.

[0087] The second quantum symmetric key refers to a pair of symmetric keys generated by the secret mail system after detecting that the target terminal has come online. These keys, consisting of a third quantum key and a fourth quantum key, are used for secondary encryption and forwarding of emails. The third quantum key, the decryption portion of the second quantum symmetric key, is sent by the secret mail system to the second centralized control station associated with the target terminal to decrypt the received second encrypted message. The fourth quantum key, the encryption portion of the second quantum symmetric key, is retained by the secret mail system and used to encrypt the stored target email to generate the second encrypted message.

[0088] The second encrypted information refers to the encrypted data generated after the secret mail system uses the fourth quantum key to encrypt the stored target email.

[0089] After storing the target email, the confidential email system starts periodic monitoring of the online status of the target terminal at a preset fixed time interval, that is, it sends a status query request to the second control station associated with the target terminal, obtains the terminal connection status feedback from the second control station, until it monitors that the target terminal switches from offline to online, triggering the subsequent process.

[0090] Subsequently, when the secret mail system confirms that the target terminal is online, it immediately generates a new pair of quantum symmetric keys - the second quantum symmetric key.

[0091] Then, the secret mail system sends the third quantum key in the second quantum symmetric key to the second centralized control station associated with the target terminal through the quantum channel.

[0092] Then, the encrypted email system calls the locally stored target email (the plaintext email that has been decrypted and temporarily stored before) and encrypts it using the fourth quantum key in the second quantum symmetric key to generate a second encrypted message that cannot be directly read.

[0093] Finally, the secret mail system sends the generated second encrypted information to the second centralized control station through the classical network channel. The second centralized control station decrypts it based on the received third quantum key and finally forwards it to the target terminal.

[0094] In this way, the secret mail system periodically monitors the online status of the target terminal at preset intervals. Then, if the target terminal is detected to be online, the secret mail system generates a second quantum symmetric key. The system then sends the third quantum key from the second quantum symmetric key to the second centralized control station. Subsequently, the secret mail system encrypts the target email using the fourth quantum key from the second quantum symmetric key to generate a second encrypted message. Finally, the secret mail system sends the second encrypted message to the second centralized control station. This avoids the key management costs required for long-term storage of encrypted information while ensuring the security of the target email transmission through secondary encryption.

[0095] See also Figure 13 In certain embodiments, the method further comprises: 058: The second centralized control station receives the third quantum key sent by the secret mail system; 059: The second centralized control station decrypts the second encrypted information according to the third quantum key to generate the target email; 060: The second centralized control station sends the target email to the target terminal.

[0096] Specifically, the second centralized control station receives the third quantum key sent by the encrypted email system via a quantum channel. Subsequently, the second centralized control station receives the second encrypted message sent by the encrypted email system via a classical network channel. Next, the second centralized control station decrypts the received second encrypted message based on the third quantum key, recovering the plaintext content of the target email. Finally, after decryption, the second centralized control station sends the target email in plaintext to the online target terminal via a secure link within the quantum local area network.

[0097] In this way, the second centralized control station receives the third quantum key sent by the encrypted mail system. Next, the second centralized control station decrypts the second encrypted message using the third quantum key, generating the target email. Finally, the second centralized control station sends the target email to the target terminal. This ensures that the target email remains protected by quantum encryption during its secondary forwarding from the encrypted mail system to the target terminal, maintaining high security throughout the entire link.

[0098] The following is a complete example to illustrate the method of sending emails when the target terminal is offline. Figure 14 , Figure 14 The signaling diagram of the email transmission method when the target terminal is offline is shown in FIG. The sending terminal is client A, the target terminal is client C, the first centralized control station is centralized control station A, and the second centralized control station is centralized control station C.

[0099] First, there's the identity authentication phase (Client A → Quantum Cryptography Management Service System → Confidential Email Server): Client A submits the authentication key Ka (including the key identifier used to identify the client) to the Quantum Cryptography Management Service System and simultaneously sends an email digest directly to the Confidential Email Server. Subsequently, the Quantum Cryptography Management Service System recognizes the key identifier as the authentication key and forwards it to the Quantum Cryptography Management Subsystem. Finally, the Quantum Cryptography Management Subsystem verifies the received Ka against the stored key Ka'. If verification succeeds, authentication is successful and the online status of Client C is determined.

[0100] Next, in the offline processing phase (encrypted email server → centralized control station A, centralized control station A → encrypted email server): While client C is offline, the encrypted email server sends the generated first quantum key K1 to centralized control station A via the quantum channel (dashed line). Centralized control station A then encrypts the original email data with the received quantum key K1, generating the first encrypted message. The encrypted email is then sent from centralized control station A to the encrypted email server. The encrypted email server then decrypts the message using the generated quantum key K2, recovering the target email and storing it.

[0101] Finally, during the online retransmission phase (encrypted email server → online detection → re-encrypted retransmission): the encrypted email server continuously monitors the online status of client C. When it determines that client C is online, it initiates the online retransmission process. The encrypted email server generates a third quantum key K3 and a fourth quantum key K4, and sends the third quantum key K3 to control station C via the quantum channel. The encrypted email server uses the third quantum key K3 to re-encrypt the temporarily stored target email, generating a second encrypted message, which it then sends to control station C via the classical network. Control station C decrypts the second encrypted message using the fourth quantum key K4 to generate the target email, which it then forwards to client C.

[0102] The present application also provides a computer-readable storage medium containing a computer program. When the computer program is executed by one or more processors, the one or more processors execute the method of the present application.

[0103] It is understood that a computer program includes computer program code. The computer program code may be in source code form, object code form, executable file, or some intermediate form. Computer-readable storage media may include any entity or device capable of carrying computer program code, recording media, USB flash drives, removable hard drives, magnetic disks, optical disks, computer memory, read-only memory (ROM), random access memory (RAM), and software distribution media.

[0104] In the description of this specification, the descriptions with reference to the terms "particularly", "further", "particularly", "understandably", etc. are intended to mean that the specific features, structures, materials or characteristics described in conjunction with the embodiments or examples are included in at least one embodiment or example of the present application. In this specification, the schematic expressions of the above terms are not intended to refer to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described may be combined in any one or more embodiments or examples in a suitable manner. In addition, those skilled in the art may combine and combine the different embodiments or examples described in this specification and the features of the different embodiments or examples, unless they are contradictory.

[0105] Any process or method description in a flowchart or otherwise described herein may be understood to represent a module, segment or portion of code comprising one or more executable instructions for implementing the steps of a specific logical function or process, and the scope of the preferred embodiments of the present application includes alternative implementations in which functions may be performed out of the order shown or discussed, including performing functions in a substantially simultaneous manner or in the reverse order depending on the functions involved, which should be understood by those skilled in the art to which the embodiments of the present application belong.

[0106] Although the embodiments of the present application have been shown and described above, it can be understood that the above embodiments are exemplary and cannot be understood as limitations on the present application. Ordinary technicians in this field can change, modify, replace and modify the above embodiments within the scope of the present application.

Claims

1. A method for transmitting mail based on quantum local area network, characterized in that: The quantum local area network includes a sending terminal, a first centralized control station that establishes a communication connection with the sending terminal, a second centralized control station, and a secret mail system. The method includes: The sending terminal sends a first authentication key and email summary information of a target email to be sent to the secret email system; The secret mail system authenticates the sending terminal according to the first authentication key and a second authentication key pre-stored in the system; When the sending terminal passes authentication, the secret mail system determines the target terminal according to the mail summary information, and the target terminal establishes a communication connection with the second centralized control station; The encrypted mail system distributes the generated first quantum symmetric key according to the online status of the target terminal at the current moment, so as to encrypt and transmit the target mail.

2. The method according to claim 1, characterized in that authenticating the sending terminal according to the first authentication key and a second authentication key pre-stored in the sending terminal, including: If the second authentication key matches the first authentication key, the encrypted mail system determines that the sending terminal passes authentication; In the case that the second authentication key does not match the first authentication key, the secret mail system determines that the sending terminal authentication fails.

3. The method according to claim 2, characterized in that The method further comprises: The secret mail system terminates the mail transmission when the sending terminal fails in authentication.

4. The method according to claim 1, wherein The distributing the generated first quantum symmetric key according to the online status of the target terminal at the current moment includes: When the target terminal is online at the current moment, the secret mail system sends the first quantum key in the first quantum symmetric key to the first centralized control station based on the quantum channel; The secret mail system sends the second quantum key in the first quantum symmetric key to the second central control station based on the quantum channel.

5. The method according to claim 4, characterized in that The method further comprises: The first centralized control station encrypts the target email according to the received first quantum key to generate first encrypted information; The first centralized control station sends the first encrypted information to the second centralized control station.

6. The method according to claim 5, characterized in that The method further comprises: The second centralized control station decrypts the first encrypted information according to the received second quantum key to generate the target email; The second centralized control station sends the target email to the target terminal.

7. The method according to claim 1, characterized in that The distributing the generated first quantum symmetric key according to the online status of the target terminal at the current moment includes: When the target terminal is in an offline state at a current moment, the secret mail system sends the first quantum key in the first quantum symmetric key to the first centralized control station based on the quantum channel.

8. The method according to claim 7, characterized in that The method further comprises: The first centralized control station encrypts the target email according to the received first quantum key to generate first encrypted information; The first centralized control station sends the first encrypted information to the encrypted mail system.

9. The method according to claim 8, characterized in that The method further comprises: The encrypted mail system receives the first encrypted information; The secret mail system decrypts the first encrypted information according to the second quantum key in the first quantum symmetric key, generates the target mail, and stores it.

10. The method according to claim 9, characterized in that The method further comprises: The secret mail system periodically monitors the online status of the target terminal at preset intervals; When monitoring that the target terminal is in an online state, the cryptographic mail system generates a second quantum symmetric key; The secret mail system sends the third quantum key in the second quantum symmetric key to the second central control station; The secret mail system encrypts the target mail according to the fourth quantum key in the second quantum symmetric key to generate a second encrypted message; The secret mail system sends the second encrypted information to the second centralized control station.

11. The method according to claim 10, characterized in that The method further comprises: The second centralized control station receives the third quantum key sent by the cryptographic mail system; The second centralized control station decrypts the second encrypted information according to the third quantum key to generate the target email; The second centralized control station sends the target email to the target terminal.

Citation Information

Patent Citations

  • Method and system for preventing tampering in mail transmission process based on quantum security key

    CN113346995A

  • Sending mail encryption method based on quantum security key

    CN113452687A

  • E-mail multi-operation encryption method and device based on quantum key

    CN114205084A

  • Establishment method, communication method, first talkback terminal, server and talkback group

    CN118660273A

  • Mail encryption method based on quantum key distribution and related equipment

    CN120017376A

Cited By

  • Mail transmission method based on encrypted mail system

    CN121239407A

  • Key charging method and authentication method for quantum local area network

    CN121308965A

  • Key authentication method for quantum encryption call

    CN121333744A

  • Communication method based on quantum communication system

    CN121485830A